Skip to main content
  1. Home
  2. Computing
  3. News

Two Israeli teenagers arrested over vDOS DDoS-for-hire service

Add as a preferred source on Google

Updated on 9-12-2016 by Jonathan Keane: Israeli police arrest two teens for allegedly running the vDOS DDoS-for-hire service

Israeli news site Haaretz reports that the Israeli national police arrested two teenagers following a tip from the FBI. The two men, Huri and Yarden Bidani, (it has not been clarified if they are related) are under house arrest for 10 days at $10,000 bail. They were also ordered to hand over their passports and are barred from using the internet for 30 days. The vDOS website is now offline.

Recommended Videos

The vDOS operators are alleged to have carried out hundreds, if not thousands, of DDoS attacks on websites on behalf of customers, earning at least $600,000 in the last two years. However the site had a policy of never attacking Israeli sites to avoid drawing too much attention to itself at home.

Original:

A web service that helped customers carry out distributed denial-of-service (DDoS) attacks on unsuspecting victims has been hacked revealing data on the customers that availed of this clandestine service.

According to security journalist Brian Krebs, vDos was hacked recently and he obtained a copy of the leaked data in July. Upon scrutinizing the database, he claims that vDOS is being run by two Israeli cybercriminals under the pseudonyms of P1st or P1st0 and AppleJ4ck, with associates in the United States.

vDOS allegedly offered monthly subscriptions to DDoS attack services, paid in bitcoin or even through PayPal, with the prices based on how long the attack would last. These DDoS attacks would launch fake traffic at victim websites, overwhelming their servers and knocking the sites offline. A particularly strong DDoS attack could cripple a site for days.

“And in just four months between April and July 2016, vDOS was responsible for launching more than 277 million seconds of attack time, or approximately 8.81 years’ worth of attack traffic,” Krebs said in his analysis. He added that he believes vDOS was handling hundreds or even thousands of concurrent attacks a day. Kreb’s analysis is based on data from April to July. Apparently all other attack data going back to the service’s founding in 2012 has been wiped away.

Krebs’ source for info on the hack was allegedly able to exploit a hole in vDOS that allowed him to access its database and configuration files. It also allowed him to source the route of the service’s DDoS attacks to four servers in Bulgaria.

Among the data dump were service complaint tickets where customers could file issues they had with the DDoS attacks they purchased. Interestingly the tickets show that the owners of vDOS declined to carry out attacks on Israeli sites to avoid drawing attention to themselves in their native land.

The duo supposedly made $618,000 according to payments records dating back to 2014 in the data dump.

“vDOS does not currently accept PayPal payments. But for several years until recently it did, and records show the proprietors of the attack service worked assiduously to launder payments for the service through a round-robin chain of PayPal accounts,” Krebs said.

The operators of the DDoS service are believed to have enlisted the help of members from the message board Hackforums in laundering the money.

Krebs warned that services like vDOS are worrisome because they make cybercrime tools available to pretty much anyone willing pay. In some cases, vDOS offered subscriptions as low as $19.99. These sorts of tools, also known as booter services, can be used ethically for testing how your site holds up against large swathes of traffic but in the wrong hands they can be abused and sold very easily.

“The scale of vDOS is certainly stunning, but not its novelty or sophistication,” Ofer Gayer of security firm Imperva said but added that this new widespread attention on DDoS service might stall them for a while.

Jonathan Keane
Jonathan is a freelance technology journalist living in Dublin, Ireland. He's previously written for publications and sites…
ChatGPT is recommending scam websites that will steal your credit card info
The chatbot is surfacing fraudulent clones of defunct retail brands, and scammers are deliberately engineering sites to game its recommendations.
ChatGPT running on a laptop.

Scammers have found a new way to reach shoppers: getting ChatGPT to do their marketing for them. According to The Guardian, scam-checking service Ask Silver found that OpenAI's chatbot is recommending fraudulent retail websites built to harvest payment details from unsuspecting buyers. The sites mimic real storefronts and use official-looking URLs, making them difficult to spot without scrutiny.

Defunct brands are a prime target

Read more
McDonald’s new AI drive-thru has to prove it can handle hungry people
After its earlier ordering bot became a punchline, McDonald’s is testing a new system that promises fewer human handoffs.
Architecture, Building, Hotel

McDonald’s is bringing AI back to the drive-thru with a new Google-backed system called ArchIQ, also known as Archy. It’s starting in five locations under the company’s broader “> NEXT” technology push, with a franchisee claiming the system has already handled more than 1 million orders.

The bigger number is the one McDonald’s needs people to trust. About 90% of those orders reportedly needed no human intervention. That sounds promising, but this is not a clean reset. Its earlier IBM-backed AI drive-thru experiment ended after viral mistakes turned automated ordering into a public punchline.

Read more
Logitech’s Mobi Fold is a pocketable folding mouse for folks who despise trackpads
Logitech’s Mobi Fold looks like a tiny productivity taco
Logitech Mobi Fold

Laptop trackpads are fine until you get really busy. Editing a spreadsheet in an airport lounge, juggling tabs in a café, or trying to do proper work on a tiny hotel desk can make you miss the convenience of a mouse. Logitech has the answer to this with the new Mobi Fold, its first ultra-portable foldable mouse.

While a small portable mouse is something people carry, many choose to skip the added bulk, simply choosing to bite the bullet with the trackpad. But the Logitech Mobi Fold can simply fold flat, and can later be unfolded when you need to work. This makes it pretty convenient to carry. Logitech even made the mouse to automatically power on when opened and turn off when folded.

Read more